04cd6b9f24
Consolidates the deferred items (reverse proxy exposing only /portal/*, TLS, SECRET_KEY, PORTAL_OPEN_LINKS off, M4 auth incl. the operator app + currently- unauthenticated operator endpoints, and the smaller code-review items) into an actionable checklist so the hardening session starts from a list, not a recall. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>